pilotctl

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core live-data purpose is partly coherent, but the actual footprint is much broader. It combines a remote installer, background updates, peer trust and messaging, file transfer, and app installation/execution, which is disproportionate for a simple data-access entrypoint and creates significant supply-chain and transitive-trust risk.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Aug 7, 2026, 04:40 PM
Package URL
pkg:socket/skills-sh/TeoSlayer%2Fpilot-skills%2Fpilotctl%2F@c609af2395bd14a9431e2ebb79b563c3562dd2f968bf26e2069877467e00b095
Security Audit — socket — pilotctl